First published: Thu Oct 22 2020(Updated: )
A divide-by-zero issue was found in dwc2_handle_packet in hw/usb/hcd-dwc2.c in the hcd-dwc2 USB host controller emulation of QEMU. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU KVM | <=5.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27661 is classified as a medium severity vulnerability due to its potential to cause denial of service.
CVE-2020-27661 can lead to a crash of the QEMU process on the host, resulting in a denial of service.
QEMU versions up to and including 5.1.1 are affected by CVE-2020-27661.
To fix CVE-2020-27661, upgrade QEMU to a version later than 5.1.1.
Currently, there are no known workarounds for CVE-2020-27661 other than upgrading to a patched version.